CVE-2024-25506: Processmaker
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.
Affected products
- Processmaker Processmaker: before 4.0 (fixed in 4.0)
Published 2024-03-28. Last modified 2026-06-17.